Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.
[
{
"deprecated": false,
"source": "https://github.com/curl/curl/commit/d530e92f59ae9bb2d47066c3c460b25d2ffeb211",
"id": "CVE-2018-16842-1bc8b2d6",
"digest": {
"line_hashes": [
"168815568103819800894446565004067456537",
"228111618259869147888575535538857014400",
"339861644007337486665567803047408870040",
"172320610373815332630135197132714421772"
],
"threshold": 0.9
},
"target": {
"file": "src/tool_msgs.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/curl/curl/commit/d530e92f59ae9bb2d47066c3c460b25d2ffeb211",
"id": "CVE-2018-16842-ea38dff0",
"digest": {
"function_hash": "276247327338978490978930240644272334443",
"length": 701.0
},
"target": {
"function": "voutf",
"file": "src/tool_msgs.c"
},
"signature_type": "Function",
"signature_version": "v1"
}
]